In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Hadoop | Apache | 2.2.0 (including) | 2.8.4 (including) |
Hadoop | Apache | 3.0.1 (including) | 3.1.0 (including) |
Hadoop | Apache | 2.9.0 (including) | 2.9.0 (including) |
Hadoop | Apache | 2.9.1 (including) | 2.9.1 (including) |
Hadoop | Apache | 3.0.0 (including) | 3.0.0 (including) |
Hadoop | Apache | 3.0.0-alpha1 (including) | 3.0.0-alpha1 (including) |
Hadoop | Apache | 3.0.0-alpha2 (including) | 3.0.0-alpha2 (including) |
Hadoop | Apache | 3.0.0-alpha3 (including) | 3.0.0-alpha3 (including) |
Hadoop | Apache | 3.0.0-alpha4 (including) | 3.0.0-alpha4 (including) |
Hadoop | Apache | 3.0.0-beta1 (including) | 3.0.0-beta1 (including) |